Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:talend:restlet:*:*:*:*:*:*:*:*", "matchCriteriaId": "AC9E4A7F-7771-4708-B405-B1273A123A41", "versionEndIncluding": "2.1.7", "vulnerable": true}, {"criteria": "cpe:2.3:a:talend:restlet:2.2:m1:*:*:*:*:*:*", "matchCriteriaId": "F2F3F5C4-8A28-44DA-A316-0BA45A4659B9", "vulnerable": true}, {"criteria": "cpe:2.3:a:talend:restlet:2.2:m2:*:*:*:*:*:*", "matchCriteriaId": "447B03C5-A6F7-4DE7-B2D2-45363F67028A", "vulnerable": true}, {"criteria": "cpe:2.3:a:talend:restlet:2.2:m3:*:*:*:*:*:*", "matchCriteriaId": "D89A5BC0-3A04-4E65-927A-201B841A55F8", "vulnerable": true}, {"criteria": "cpe:2.3:a:talend:restlet:2.2:m4:*:*:*:*:*:*", "matchCriteriaId": "2B6A3AB9-7B1A-4091-B146-E2D387A7B09E", "vulnerable": true}, {"criteria": "cpe:2.3:a:talend:restlet:2.2:m5:*:*:*:*:*:*", "matchCriteriaId": "1B31BC77-A478-4D34-A516-42DD76B3C407", "vulnerable": true}, {"criteria": "cpe:2.3:a:talend:restlet:2.2:m6:*:*:*:*:*:*", "matchCriteriaId": "6D40623A-AF01-4B7F-A4C3-A473CF162B70", "vulnerable": true}, {"criteria": "cpe:2.3:a:talend:restlet:2.2:rc1:*:*:*:*:*:*", "matchCriteriaId": "6ABBB358-7EDD-42F4-A0CF-8E40269C623A", "vulnerable": true}, {"criteria": "cpe:2.3:a:talend:restlet:2.2:rc2:*:*:*:*:*:*", "matchCriteriaId": "9390FCEC-1B7E-49EF-A8C6-A2D0FDEB7E82", "vulnerable": true}, {"criteria": "cpe:2.3:a:talend:restlet:2.2:snapshot:*:*:*:*:*:*", "matchCriteriaId": "209472D5-A372-4FB6-ABF7-A05A181355A2", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages."}, {"lang": "es", "value": "La extensi\u00f3n XStream en HP Fortify SCA versiones anteriores a 2.2 RC3, permite a atacantes remotos ejecutar c\u00f3digo arbitrario por medio de una deserializaci\u00f3n no segura de mensajes XML."}], "id": "CVE-2014-2228", "lastModified": "2024-11-21T02:05:53.127", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 7.5, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "version": "2.0"}, "exploitabilityScore": 10.0, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2020-02-19T14:15:10.233", "references": [{"source": "cve@mitre.org", "tags": ["Exploit", "Third Party Advisory"], "url": "https://web.archive.org/web/20140425095352/http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Remote-code-execution-and-XML-Entity-Expansion-injection/ba-p/6403370"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit", "Third Party Advisory"], "url": "https://web.archive.org/web/20140425095352/http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Remote-code-execution-and-XML-Entity-Expansion-injection/ba-p/6403370"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-776"}], "source": "nvd@nist.gov", "type": "Primary"}]}